regulations
High-Risk AI System
An AI system subject to heightened legal obligations because of what it's used for — not because of the underlying technology — typically because it materially affects access to employment, credit, healthcare, housing, or legal standing.
"High-risk" is a legal classification, not a technical one — it describes what a system is used for, not what kind of model powers it. A simple logistic regression used to screen job candidates can be high-risk; a large language model used for internal code review generally is not.
How the classification works under the EU AI Act
Under the EU AI Act, a system becomes high-risk through one of two tracks: it's a safety component of a product already covered by existing EU product-safety law, or it falls into one of the specific use-case categories listed in Annex III — employment decisions, creditworthiness evaluation, access to essential services, biometric categorization, and others. See our full breakdown of Article 6 classification for how the two-step test actually applies, including the exemption most teams misuse.
How U.S. state laws draw the line differently
U.S. state laws generally use similar language — "consequential decision," "high-risk artificial intelligence system" — but define the triggering use cases independently, state by state, rather than through a shared list like the EU's Annex III. Colorado's SB 205, for example, defines a high-risk system by reference to consequential decisions in employment, education, lending, housing, healthcare, insurance, and legal services. The categories overlap heavily with the EU's list but aren't identical, which is exactly why a system can be high-risk in one jurisdiction and outside a comparable category in another.
Why the classification is the hinge point
Classification isn't academic — it's the trigger for a specific, often extensive set of obligations: risk management processes, data governance requirements, technical documentation, human oversight measures, and (in most U.S. state frameworks) a documented impact assessment. Getting the classification wrong in either direction has real cost: over-classifying burns compliance resources on systems that don't need it; under-classifying leaves a genuinely consequential system without the safeguards the law requires.
Suggested next reading
ai governance
AI Governance
risk management
Algorithmic Bias
regulations eu
The EU AI Act
regulations us colorado